Skip to main content

Vendor/product archive

juniper / junos CVEs

Beta · best-effort

786 CVEs tagged to juniper / junos32 Critical, 419 High, 333 Medium, 2 Low, 0 Unrated.

CVE-2021-0205

Published Jan 15, 2021

When the "Intrusion Detection Service" (IDS) feature is configured on Juniper Networks MX series with a dynamic firewall filter using IPv6 source or destination prefix, it may inc…

CVSS 5.8 · Medium

CVE-2021-0204

Published Jan 15, 2021

A sensitive information disclosure vulnerability in delta-export configuration utility (dexp) of Juniper Networks Junos OS may allow a locally authenticated shell user the ability…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0203

Published Jan 15, 2021

On Juniper Networks EX and QFX5K Series platforms configured with Redundant Trunk Group (RTG), Storm Control profile applied on the RTG interface might not take affect when it rea…

CVSS 8.6 · High

CVE-2021-0202

Published Jan 15, 2021

On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPC (Modular Port Concentrator) where Integrated Routing and Bridging (IRB) interface is configured and i…

CVSS 7.5 · High

CVE-2020-1688

Published Oct 16, 2020

On Juniper Networks SRX Series and NFX Series, a local authenticated user with access to the shell may obtain the Web API service private key that is used to provide encrypted com…

CVSS 6.5 · Medium

CVE-2020-1687

Published Oct 16, 2020

On Juniper Networks EX4300-MP Series, EX4600 Series and QFX5K Series deployed in (Ethernet VPN) EVPN-(Virtual Extensible LAN) VXLAN configuration, receipt of a stream of specific…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1686

Published Oct 16, 2020

On Juniper Networks Junos OS devices, receipt of a malformed IPv6 packet may cause the system to crash and restart (vmcore). This issue can be trigged by a malformed IPv6 packet d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1684

Published Oct 16, 2020

On Juniper Networks SRX Series configured with application identification inspection enabled, receipt of specific HTTP traffic can cause high CPU load utilization, which could lea…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1683

Published Oct 16, 2020

On Juniper Networks Junos OS devices, a specific SNMP OID poll causes a memory leak which over time leads to a kernel crash (vmcore). Prior to the kernel crash other processes mig…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1680

Published Oct 16, 2020

On Juniper Networks MX Series with MS-MIC or MS-MPC card configured with NAT64 configuration, receipt of a malformed IPv6 packet may crash the MS-PIC component on MS-MIC or MS-MPC…

CVSS 5.3 · Medium

CVE-2020-1679

Published Oct 16, 2020

On Juniper Networks PTX and QFX Series devices with packet sampling configured using tunnel-observation mpls-over-udp, sampling of a malformed packet can cause the Kernel Routing…

CVSS 7.5 · High

CVE-2020-1678

Published Oct 16, 2020

On Juniper Networks Junos OS and Junos OS Evolved platforms with EVPN configured, receipt of specific BGP packets causes a slow memory leak. If the memory is exhausted the rpd pro…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-1673

Published Oct 16, 2020

Insufficient Cross-Site Scripting (XSS) protection in Juniper Networks J-Web and web based (HTTP/HTTPS) services allows an unauthenticated attacker to hijack the target user's HTT…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1672

Published Oct 16, 2020

On Juniper Networks Junos OS devices configured with DHCPv6 relay enabled, receipt of a specific DHCPv6 packet might crash the jdhcpd daemon. The jdhcpd daemon automatically resta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1671

Published Oct 16, 2020

On Juniper Networks Junos OS platforms configured as DHCPv6 local server or DHCPv6 Relay Agent, Juniper Networks Dynamic Host Configuration Protocol Daemon (JDHCPD) process might…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1670

Published Oct 16, 2020

On Juniper Networks EX4300 Series, receipt of a stream of specific IPv4 packets can cause Routing Engine (RE) high CPU load, which could lead to network protocol operation issue a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1669

Published Oct 16, 2020

The Juniper Device Manager (JDM) container, used by the disaggregated Junos OS architecture on Juniper Networks NFX350 Series devices, stores password hashes in the world-readable…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1668

Published Oct 16, 2020

On Juniper Networks EX2300 Series, receipt of a stream of specific multicast packets by the layer2 interface can cause high CPU load, which could lead to traffic interruption. Thi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1667

Published Oct 16, 2020

When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiser…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1665

Published Oct 16, 2020

On Juniper Networks MX Series and EX9200 Series, in a certain condition the IPv6 Distributed Denial of Service (DDoS) protection might not take affect when it reaches the threshol…

CVSS 5.3 · Medium

CVE-2020-1664

Published Oct 16, 2020

A stack buffer overflow vulnerability in the device control daemon (DCD) on Juniper Networks Junos OS allows a low privilege local user to create a Denial of Service (DoS) against…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1662

Published Oct 16, 2020

On Juniper Networks Junos OS and Junos OS Evolved devices, BGP session flapping can lead to a routing process daemon (RPD) crash and restart, limiting the attack surface to config…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 476-500 of 786 CVEsPage 20 of 32